Malware Families page 42 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Retro trojanspyware
- Retro is a stealthy malware designed to evade detection while gathering sensitive information primarily from governmental and financial…
- RevC2 ratbackdoor
- RevC2 is a remote access trojan (RAT) primarily used for cyber espionage against government, financial, and technology sectors.
- RevCode trojanspyware
- RevCode is a sophisticated trojan frequently associated with targeted attacks against tech companies.
- Revenant rat
- According to its author, Revenant is a 3rd party agent for Havoc written in C, and based on Talon.
- Revenge RAT rat
- Also known as Revetrat. Revenge RAT is a freely available remote access tool written in .NET (C#).
- Revenge Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Revenge-RAT rat
- Revenge v0.1 was a simple tool, according to a researcher known as Rui, who says the malware’s author didn’t bother obfuscating the RAT’s…
- ReverseRAT rat
- ReverseRAT is a remote access trojan primarily used for espionage operations.
- Reveton ransomware
- Reveton is a type of ransomware known for displaying a lock screen imitating law enforcement agencies to trick users into paying a fine…
- Reveton ransomware ransomware
- A ransomware family that targets users from certain countries or regions.
- Revive trojancredential-stealer
- According to PCrisk, Revive is the name of a banking Trojan targeting Android users (customers of a specific Spanish bank).
- Revolution ransomware
- Revolution is a type of ransomware known for encrypting victims' data and demanding a ransom for its release.
- Rex ratspyware
- Rex is a sophisticated remote access tool used by threat actors for espionage operations, primarily targeting government and technology…
- Reyptson ransomware
- Reyptson is a ransomware that specifically targets users in Spain.
- Rhadamanthys credential-stealer
- According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected…
- Rhino ransomware
- Rhino is a ransomware variant known for encrypting files and demanding a ransom from victims.
- Rhysida (ELF) ransomware
- Rhysida is a ransomware family known for targeting sectors such as government and healthcare.
- Rhysida (Windows) ransomware
- Rhysida is a ransomware family that primarily targets organizations across various sectors, including healthcare, education, and government.
- Rietspoof downloaderdropperbotnet
- Rietspoof is malware that mainly acts as a dropper and downloader, however, it also sports bot capabilities and appears to be in active…
- Rifdoor rat
- Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.
- Rijndael ransomware
- Rijndael is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
- Rikamanu backdoorrat
- Rikamanu is an advanced persistent threat known for its backdoor and remote access trojan capabilities, primarily targeting governmental…
- Riltok trojancredential-stealer
- Riltok is banking malware that uses phishing popups to collect user credentials.
- Rincrypt ransomware
- Rincrypt is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
- Rincux trojan
- Rincux is a Trojan malware known for targeting financial institutions and technology sectors.
- Ripper ATM trojan
- Ripper ATM is a malware family designed to target and exploit ATM systems.
- RiseLoader loaderdropper
- RiseLoader is a new malware loader family first observed in October 2024.
- RisePro credential-stealerdownloadertrojan
- RisePro is a stealer that is spread through downloaders like win.privateloader.
- Rising Sun backdoortrojan
- Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019.
- Roaming Mantis trojan
- Roaming Mantis is an Android Trojan that has been predominantly spreading through DNS hijacking and smishing campaigns, targeting users…
- RoarBAT wiper
- According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.
- RobbinHood ransomware
- RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.
- RobinHood ransomware
- Also known as HelpYemen, RobbinHood. Detected in April 2019. Known for paralyzing the cities of Baltimore and Greenville. Probably also exfiltrate data
- Roboto botnetddos
- P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows…
- Rockloader loader
- Rockloader is a malware loader known for downloading additional malicious payloads onto infected systems.
- Rofin
- Rofin is a malware entity with limited available information, lacking a detailed description of its functionalities and target scope.
- Roga ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Rogue
- Rogue is a malware with limited publicly available information.
- Rogue HT ransomware
- Rogue HT is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- RogueRobin backdoorrat
- RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.
- RogueRobinNET backdoortrojan
- RogueRobinNET is a .NET variant of the PS1.RogueRobin, known for targeting government and defense sectors in the Middle East.
- Rokku ransomware
- Rokku is a type of ransomware potentially associated with the Chimera malware family.
- RollSling rat
- RollSling is a Remote Access Trojan (RAT) used primarily for cyber-espionage purposes, targeting government and public sector organizations.
- Rombertik spywarecredential-stealer
- Also known as CarbonGrabber. Rombertik is a sophisticated spyware and credential-stealer known for its anti-analysis and destructive capabilities.
- Romeo(Alfa,Bravo, ...) rat
- Romeo is a remote access tool (RAT) used mainly for cyber espionage.
- Rontok ransomware
- Rontok is a ransomware type of malware designed to encrypt files on the infected system, demanding a ransom payment for their release.
- Rook ransomware
- Rook is a ransomware family known for targeting various sectors such as healthcare, financial services, and government entities.
- Roopirs backdoortrojan
- Roopirs is a sophisticated malware family known to target financial and government sectors, particularly in Eastern Europe.
- Roopy
- Roopy is a malware sample with limited information available.
- Rootnik rootkittrojan
- Rootnik is an Android-based malware family known for its ability to escalate privileges and maintain persistence.
- Rorschach Ransomware ransomware
- Also known as BabLock. Rorschach Ransomware, also known as BabLock, is a sophisticated ransomware strain designed to encrypt the victim's files and demand a…
- Roseam loader
- Also known as PisLoader. Roseam, also known as PisLoader, is a malware family primarily used as a loader for delivering various types of payloads.
- RoshaLock ransomware
- Ransomware Stores your files in a password protected RAR file
- Roshtyak backdoor
- A DLL backdoor distributed by Raspberry Robin.
- RotaJakiro backdoor
- RotaJakiro is a 64-bit Linux backdoor used by APT32.
- Rotexy ransomwarespywaretrojan
- Rotexy is an Android banking malware that has evolved over several years.
- RotorCrypt(RotoCrypt, Tar) Ransomware ransomware
- Also known as RotorCrypt, RotoCrypt, Tar Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- Rottie3 ratbackdoor
- Rottie3 is a remote access trojan (RAT) that provides attackers with persistent backdoor access to compromised systems.
- Rover spyware
- Rover is malware suspected of being used for espionage purposes.
- Rovnix loaderrootkit
- Also known as BkLoader, Cidox, Mayachok. Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves.
- Royal ransomware
- Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023.
- Royal DNS backdoor
- RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
- Royal Ransom (ELF) ransomware
- Also known as Royal, Royal_unix. According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be…
- Royal Ransom (Powershell) downloaderransomware
- Toolkit downloader used by Royal Ransomware group, involving GnuPG for decryption.
- Royal Ransom (Windows) ransomware
- Royal Ransom is a type of ransomware that targets various industries by encrypting data and demanding ransom payments for decryption keys.
- RoyalCli backdoor
- RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines.
- RozaLocker Ransomware ransomware
- Also known as Roza. This is most likely to affect English speaking users, since the note is written in English.
- Rozena rat
- Rozena is a Remote Access Trojan (RAT) that provides attackers with unauthorized access and control over affected systems.
- Rozlok ransomware
- Rozlok is a notorious ransomware encrypting victim's files and demanding payment in cryptocurrency.
- Rransom ransomware
- Rransom is a ransomware family known for encrypting files and demanding a ransom payment for decryption.
- Rshell rat
- Rshell is a remote access tool (RAT) used by cybercriminals to gain unauthorized access to victim machines.
- RuMMS spywaretrojan
- RuMMS is an Android malware family known for its ability to collect sensitive information from infected devices.
- Rubeus credential-stealer
- Rubeus is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.
- Ruby ransomware
- Ruby is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- Ruckguv rat
- Ruckguv is a remote access tool (RAT) primarily used in cyber-espionage campaigns targeting government sectors.
- RudeDevil ratbackdoor
- RudeDevil is a remote access Trojan (RAT) primarily used for espionage and data stealing from government, financial, and tech sectors.
- Rugmi trojanbackdoor
- Also known as Penguish. Rugmi, also known as Penguish, is a sophisticated backdoor trojan used primarily for cyber-espionage activities.
- Ruler exploit-kit
- Ruler is a tool to abuse Microsoft Exchange services.
- Rumish rat
- Rumish is a remote access tool (RAT) primarily targeting government, financial, and telecommunications sectors.
- RunExeMemory ransomware
- RunExeMemory is a ransomware variant that encrypts files on infected systems and demands a ransom payment in cryptocurrency for file…
- RunForestRun exploit-kit
- Also known as Blackhole, Sutra. Active around 2012-2013, this family deployed small JavaScript snippets on infected websites to load exploit kit scripts from…
- Running RAT ratkeyloggertrojan
- Also known as running_rat. NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files.
- RunningRAT rat
- RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and…
- Runsomewere ransomware
- Ransomware Based on HT/EDA2 Utilizes the Jigsaw Ransomware background
- Rurktar trojanspyware
- Also known as RCSU. Rurktar, also known as RCSU, is a trojan spyware used for unauthorized access and information extraction.
- Rush ransomware
- Rush is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption keys.
- RushDrop dropperrat
- Also known as ChronosRAT. According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
- Russenger ransomware
- Russenger is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
- Russian EDA2 ransomware
- Russian EDA2 is a strain of ransomware designed to encrypt files on infected systems and demand a ransom for decryption.
- Russian Globe Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- RussianRoulette ransomware
- RussianRoulette is a ransomware variant evolving from the Philadelphia ransomware, aimed at encrypting user data to demand a ransom payment.
- RustBucket (OS X) rat
- RustBucket is a malware designed to target Mac OS X systems, often used for gaining remote access to compromised machines.
- RustBucket (Windows) rat
- RustBucket is a Remote Access Trojan (RAT) targeting Windows systems, primarily aimed at compromising governmental and financial…
- Rustock botnet
- Rustock is a sophisticated botnet malware that was primarily used for sending spam emails.
- Rustonotto trojanrat
- Also known as CHILLYCHINO. Rustonotto, active since June 2025, is a Rust-compiled malware, representing the first known instance of APT37 leveraging Rust-based…
- RustyClaw downloader
- According to Proofpoint, RustyClaw is a downloader written in Rust
- RustyRocket trojanspyware
- Written in Rust and designed for both Windows and Linux environments, RustyRocket enables WorldLeaks affiliates to steal data through…
- RustyWater rat
- Also known as Archer RAT / RUSTRIC. RustyWater is a Rust-based implant used by MuddyWater.
- Ryuk ransomware
- Ryuk is a ransomware designed to target enterprise environments that has been used in attacks since at least 2018.
- Ryuk Stealer credential-stealerspyware
- Also known as Sidoh. Information Stealer that searches for sensitive documents and uploads its results to an FTP server.